Executive brief
A vulnerability exists in the User Interface component of Oracle Inventory Optimization, a tool used by businesses to manage supply chain stock levels. A low-privileged user could potentially disrupt the application's availability, leading to a partial service outage. While the impact is limited to a partial denial of service, it could interfere with routine inventory management operations.
Technical details
This vulnerability affects the User Interface component of Oracle Inventory Optimization within the Oracle E-Business Suite. It is classified as a denial of service (DoS) vulnerability that is considered difficult to exploit. An attacker requires network access via HTTP and low-level user privileges to successfully execute the attack. If exploited, the vulnerability allows the attacker to cause a partial denial of service, impacting the availability of the Inventory Optimization module. The issue is present in supported versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Inventory Optimization 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.